Flagship dossier · No. II
Defensive open-source intelligence for infrastructure owners — intelligence, presented as evidence
OSINT tools dump data. Exhibit turns it into testimony: every finding is an auditable claim with provenance, a claim tier, a review date, and a falsifier. The pipeline once fabricated a 90%-confidence finding from a re-served scan. The postmortem became the architecture — so the machine that collects the evidence cannot also be the one that believes it.
A third-party scan found twenty open ports on marcusrichards.dev — a finding the pipeline carried at 90% confidence and a human almost sent to a domain owner. Independent verification showed one open port: the vendor had re-served a cached scan. The system that believed its own evidence was rebuilt as two machines instead of one: the collector and the verifier, with a human holding the deciding vote. AI may propose or summarize — AI never independently verifies.
Connectors fetch from public sources — certificate transparency, DNS, RDAP, GitHub, urlscan — and record each observation with its source, timestamp, and exact bytes hashed.
Claims are fused across sources, scored transparently, and tiered. A claim seen by two independent sources outranks a claim seen by one — and the machine may never close the gap to certainty alone.
The review queue is the product's conscience: no finding reaches a report without a human approving, rejecting, or deferring it — and the decision is part of the record.
Three subsystems run in sequence, each with its own falsifier. Nothing is trusted across a boundary without being re-examined there.
Eleven public sources, one claim ledger. Every claim carries its source parameters, timestamp, response state, raw-byte hash, provider identifiers, a terms-of-service snapshot, attribution, claim tier, review date, and falsifier. A terms-of-service gate stands in front of the third-party verdicts: verdicts from vendors whose terms forbid redistribution are read, not repeated.
Subdomains from the certificate firehose. A labeled 20-fixture evaluation reported 1.000 precision and 1.000 recall on the fixture set — presented exactly as what it is, self-consistency against the labeled fixtures, not validation against the wild internet. A shadow-eval harness watches for the day the wild disagrees with the fixtures.
Change detection that remembers what it couldn't see. A blind source that recovers can masquerade as a new threat; the sentinel records per-source coverage so recovery produces an informational SOURCE RECOVERED note instead of a false alert. Genuine new exposures still alert. A weekly pipeline runs the full sequence on marcusrichards.dev itself.
Exhibit has run thirteen assessment passes against marcusrichards.dev — the author's own production surface — under a 41-test suite, with every claim stored in an append-only SQLite ledger. The current posture: risk 0, no adverse signals.